Trojan

Trojan-PSW.Win32.Delf.ahwk removal

Malware Removal

The Trojan-PSW.Win32.Delf.ahwk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Delf.ahwk virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan-PSW.Win32.Delf.ahwk?


File Info:

name: 45B1F03F570D1F9C39D5.mlw
path: /opt/CAPEv2/storage/binaries/df7896faf63ab8c5bcab04cf29d879b872db78ebd640c3f309c64207898e5a26
crc32: 3BED725A
md5: 45b1f03f570d1f9c39d5058f5443a2e0
sha1: a55c9217b32ca7429539729d62c6a36aa560451f
sha256: df7896faf63ab8c5bcab04cf29d879b872db78ebd640c3f309c64207898e5a26
sha512: d8de698c321d74732018fa192f106ee277c3e97e140558ef7e058899a8c3835cf1b0553a233e654ef8cea544792f0e9959efb8f3f4a8d5849570d67c29665354
ssdeep: 24576:nqVppRPCAg65avrDR9R+RVO8yrTcAdHQ6aEzHuJBeSFZBPNH5THifFsmu70QVy+Z:stg9RXr9rOJwSdPfHiiFrfEnPBc/CDu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5E56D227A88643BD2BB0F3A4837D6549C3F7B617A16EC1F57E409CC8E755406E3A60B
sha3_384: f44358a2853d5c00c726765e5b2ed6486901228db4a29538fbdb215c2d311ff8c7d01bd19c1b24d1bf2a79e55378721a
ep_bytes: 558bec83c4f0b8084b6700e850b3d8ff
timestamp: 2015-01-05 18:01:34

Version Info:

CompanyName: Microsoft
FileVersion: 7.0.0.100
InternalName: Skype
OriginalFilename: Security
ProductName: Skype
ProductVersion: 7.0.0.100
Translation: 0x0409 0x04e4

Trojan-PSW.Win32.Delf.ahwk also known as:

LionicTrojan.Win32.Delf.i!c
DrWebTrojan.DownLoader12.51370
MicroWorld-eScanGen:Trojan.Heur.cV0@r88!UtnO
FireEyeGen:Trojan.Heur.cV0@r88!UtnO
SkyhighBehavesLike.Win32.Dropper.wh
McAfeeGenericR-OYC!45B1F03F570D
Cylanceunsafe
ZillyaTrojan.Delf.Win32.112130
SangforInfostealer.Win32.Agent.Vwj3
AlibabaTrojanPSW:Win32/Generic.a552616f
BitDefenderThetaAI:Packer.41E8E8C41C
VirITTrojan.Win32.Agent.BIZR
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Delf.ahwk
BitDefenderGen:Trojan.Heur.cV0@r88!UtnO
NANO-AntivirusTrojan.Win32.ThreatSysVenFakbased.dmferi
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.1154a91d
EmsisoftGen:Trojan.Heur.cV0@r88!UtnO (B)
F-SecureTrojan.TR/Spy.Agent.3183616.1
VIPREGen:Trojan.Heur.cV0@r88!UtnO
TrendMicroTROJ_GEN.R002C0PAO24
SophosMal/Generic-R
GDataGen:Trojan.Heur.cV0@r88!UtnO
WebrootW32.Trojan.Gen
AviraTR/Spy.Agent.3183616.1
Antiy-AVLTrojan[PSW]/Win32.Delf
ArcabitTrojan.Heur.EDCEDA
ViRobotTrojan.Win32.S.Agent.3183616.A
ZoneAlarmTrojan-PSW.Win32.Delf.ahwk
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win32.Gen
VBA32TScope.Trojan.Delf
ALYacGen:Trojan.Heur.cV0@r88!UtnO
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PAO24
RisingTrojan.Generic@AI.100 (RDML:tjtSx7PvNxYHHQyjNNZd5w)
YandexTrojanSpy.Agent!09hWe8uD/IE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan-PSW.Win32.Delf.ahwk?

Trojan-PSW.Win32.Delf.ahwk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment